# Logstash wont add date to logs

**URL:** https://discuss.elastic.co/t/logstash-wont-add-date-to-logs/29267
**Category:** Logstash
**Created:** [September 14, 2015, 4:47pm UTC](https://discuss.elastic.co/t/logstash-wont-add-date-to-logs/29267 "2015-09-14T16:47:41Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![mgirndt](https://avatars.discourse-cdn.com/v4/letter/m/fbc32d/32.png) [@mgirndt](https://discuss.elastic.co/u/mgirndt)
#### Post date: [September 14, 2015, 4:47pm UTC](https://discuss.elastic.co/t/logstash-wont-add-date-to-logs/29267/1 "2015-09-14T16:47:41Z")

</div>

How can I get logstah add the date field that I have added to my jboss logs?  
The log looks like:  
August 10 2015 10:07:01,048 INFO [org.jboss.as.naming] (ServerService Thread Pool -- 38) JBAS011800: Activating Naming Subsystem

My indexer is:  
input {  
redis {  
host =\> "XXX.XXX.XXX.XXX"  
port =\> 6379  
data\_type =\> "list"  
key =\> "logstash"  
codec =\> "json"  
}  
}  
filter {  
if [type] == "jboss" {  
grok {  
match =\> [  
"message",  
"%{TIME:time} %{LOGLEVEL:level}.\*[(?[^]]+)] ((?[^)]+)) %{GREEDYDATA:message}"  
]  
overwrite =\> ["message"]  
}  
}  
multiline {  
type =\> "jboss"  
pattern =\> "^\s"  
what =\> "previous"  
}  
}  
output {  
elasticsearch {  
host =\> "XXX.XXX.XXX.XXX"  
port =\> 9300  
}  
}

I need the time field to show both the log date and the time.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [September 14, 2015, 5:04pm UTC](https://discuss.elastic.co/t/logstash-wont-add-date-to-logs/29267/2 "2015-09-14T17:04:26Z")

</div>

Use a [date filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html) to parse the `time` field and make sure it includes the date too when you create the field with the grok filter.

---

<div class="post-metadata">

### Author: ![mgirndt](https://avatars.discourse-cdn.com/v4/letter/m/fbc32d/32.png) [@mgirndt](https://discuss.elastic.co/u/mgirndt)
#### Post date: [September 14, 2015, 6:50pm UTC](https://discuss.elastic.co/t/logstash-wont-add-date-to-logs/29267/3 "2015-09-14T18:50:19Z")

</div>

I'm not sure how to write it or where in the grok filter to put it.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [September 14, 2015, 7:26pm UTC](https://discuss.elastic.co/t/logstash-wont-add-date-to-logs/29267/4 "2015-09-14T19:26:20Z")

</div>

Well, change the beginning of your grok expression like this:

```
grok {
  match => [
    "message",
    "(?<time>%{MONTH} %{MONTHDAY} %{YEAR} %{TIME}) %{LOGLEVEL:level} ..."
  ]
}

```

This should leave you with a `time` field containing e.g. "August 10 2015 10:07:01,048". A date filter to parse this probably looks like this:

```
date {
  match => ["time", "MMM dd YYYY HH:mm:ss,SSS"]
  remove_field => ["time"]
}

```

I also suggest that you place the multiline filter first (followed by the grok and date filters).

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 5:29am UTC](https://discuss.elastic.co/t/logstash-wont-add-date-to-logs/29267/5 "2017-07-06T05:29:12Z")

</div>


